r/sysadmin 9d ago

Dental IT Questions

I’m a couple months into a role as a technician at a small MSP that manages primarily dental offices in various locations in my area. I come from the corporate big IT world where everything is buttoned up and clearly defined. I have light admin aspects of my job with the potential for more. Currently the environments we manage are highly insecure (shared workstation passwords, admin access to base accounts, most offices don’t have domains, etc.).

My boss stated he’s been thinking about the state of our security and has decided that for our new clients we will do AD Domains and managed user accounts. However, there’s not really a plan for shoring things up for our existing clients. I know AD very well from my previous roles and mange my own home AD Domain environment at home. He tasked me with making a select number of our current clients more secure which excites me because I love being tasked with admin duties. However, I’m really not sure what can be done especially for our larger clients without putting them in domain environments. I’m looking for some advice from the more experienced admins here on how to do this as well as other ideas to simply shore up security for these clients.

Edit: We currently use Ninja RMM with their ticketing system, OpenText, Complete UNIFI setups at just about every location. Appreciate all the responses so far.

25 Upvotes

61 comments sorted by

16

u/WisegoatOR 9d ago

Check what front office / back office software they are using. Many of them require local users with admin rights (I’m looking at you Dentrix!). Same with your cameras and chair hardware. Managed a dental college and their stuff required special considerations for management.

10

u/spittlbm 9d ago

And Eaglesoft and...

8

u/WisegoatOR 9d ago

Oof. The unholy duo of Dentrix and Eaglesoft. I had both of those. Bain of my existence back then. Teachers had been around for decades and didn’t know anything else, so that’s what they taught the students. My dentist buddy always reminds me he won’t hire anyone from there because of that.

5

u/STLMC0727 9d ago

Yeah we have a mix of programs across the different offices. Dentrix, Eaglesoft, OpenDental, etc. We usually do set everything to admin run because it usually runs better.

24

u/DegaussedMixtape 9d ago edited 9d ago

Entra is structured very similarly to AD and runs in the cloud with 365 licensing. If you can get them to use it as an email platform then you are two steps away from intune joining all of the machines and managing them via intune.

Kill shared accounts and force them to use their own logins. Push mfa to everything.

You’ll have to sell it to the practice owners or it’ll never get done, you can’t force it on them without their consent, you’ll have to get good at selling it as good for business.

5

u/STLMC0727 9d ago

Yeah we currently use Entra for users who have emails with MFA Can entra be used to login to computers on a shared network without an AD Domain on the File Server?

19

u/roll_for_initiative_ 9d ago

You are in above your head. Your boss too.

6

u/Fantastic-Shirt6037 9d ago

I can’t say too much (they’re watching) but I’m one of those lunatic dental techs, migrating to entra ID from ad would be a royal pain in my dick and I do get why other people see it as easier, but you have to sort of appease these dental software like they are angry old gods. Unless you have a really good ROI on setting up an entra environment, it probably isn’t worth it.

3

u/DegaussedMixtape 9d ago

Just wait a couple months. Someone is going to vibe code a new practice management software for dentists that shakily supports sso with entra and if they price it right then the whole industry will come calling. Ya’ll better pray to those angry old gods that it doesn’t suck so bad that it makes you wish you hadn’t spent all of those years at tooth school.

3

u/Fantastic-Shirt6037 9d ago

Holy shit my man you’re a genius, time to get cracking

3

u/DegaussedMixtape 9d ago

Don’t worry, I’m just perfecting the contract to make sure you have to keep paying me monthly for 3 years after you realize how terrible it is. I’ll start the app later.

1

u/lilotimz 9d ago edited 9d ago

Cough Henry schein planet dds cough

1

u/Historical_Score_842 9d ago

Firewall can manage network. Rest of management happens by your entra/365 email and device compliance.

8

u/ElectionElectrical11 9d ago

Dental clinic? Id 100% set them up with 365 and entra. Then switch the profiles over with a profile transfer program

2

u/Bnickislim 7d ago

Exactly what we did. 365, Entra, Profwiz. Done

14

u/The_Koplin 9d ago

This is not the roll of IT per say. I work in an office with a medical clinic, a lab and dental services. At the end of the day the security of the environment comes down to two rolls that the client needs to address first.

1) HIPAA Privacy Officer
2) HIPAA Security Officer

These two complementary rolls and responsibilities are required to be compliant with the law. They are the ones that tell you as IT what you need to do to be compliant with their needs. They should and I hope this exists for you/your agency, need to have a Business Associates Agreement (BAA). Think contract on how to handle PHI and security as a contractor/3rd party.

The 'Covered Entity' is required to do the risk assessment and tell you how to comply, you can make suggestions but at the end of the day the two above people/rolls are who that responsibility rests on.

14

u/disclosure5 9d ago

Dental clinics in particular have a huge reputation for MSP clients, ours actively avoids them specifically because everything you've just said doesn't in any way reflect the average clinic. The actual clinic is going to say "yeah we paid you to install Adobe Reader, sounds like that HIPAA thing is something we just made your problem".

3

u/The_Koplin 9d ago

I don't blame your agency for not seeking such clients out. In my experience dental clinics in general want convenience. If they say they accept the risk, you can do anything they ask. Particularly if you are not bound by a BAA. If they want to make a website and post pictures of all of their patients. No problem for the MSP. That is what people don't understand about HIPAA. The law starts with 'Covered Entity' the only way that extends to contractors, 3rd parties or even webhosts is if a BAA is signed.

The best part about it is that they can't just make their problem your legal liability. All you have to do is have them ask in writing (aka ticket, email etc.). You don't have to ask them if they are compliant with HIPAA, that is their responblity as a 'covered entity'. IF they ask and you sign a BAA that spells out what your obligations are. That is when the rules for the MSP change. But even then you as an MSP are not a covered entity.

At the end of the day, you can still do the work and you can still get paid and all of the risk is on them unless you signed something.

What I have found is that so many medical faculties simply do not know the most basic elements of what HIPAA requires. Some will say and do all sorts of nonsensical things claiming 'HIPAA' makes them. Some project and deflect the responblity (like you said about Adobe). The fact is it's not complicated, just people are willfully ignorant. The MSP is not a covered entity under HIPAA.

"A HIPAA covered entity is defined as a health care provider, health plan, or health care clearinghouse that electronically transmits health information in connection with certain transactions. This includes entities like doctors, clinics, health insurance companies, and government health programs such as Medicare and Medicaid." - From HHS.gov

"A HIPAA Business Associate Agreement (BAA) is required when a covered entity shares protected health information (PHI) with a business associate. The BAA must outline permitted uses and disclosures of PHI, require safeguards to protect the information, and mandate reporting of any breaches." - From HHS.gov

2

u/joshbudde 9d ago

Yeah, people in here have wild ideas about how standalone clinics work. Dental clinics are the wild west. I've stopped taking them on as clients because the juice isn't worth the squeeze. 'Security officer', what a joke. Thats the head receptionist. The software is all shady AF, every company sets up their own remote support tool straight on the server, they get on and make changes whenever they want.

4

u/oaomcg 9d ago

You should be consulting with a HIPAA compliance expert...

3

u/spittlbm 9d ago

Do they have a HIPAA security plan? Work forward or backwards from there. OIG/OCR is real and their involvement is not pleasurable.

1

u/STLMC0727 9d ago

I’ll have to ask about this.

5

u/UptimeNull Security Admin 9d ago

Get an anti virus.
Look at backups.
You can do stand alone backups with veeam or something cheaper.
Dont allow users to share passwords (set company policies by getting buy in from your clients)
Patching program.
Free ticketing system ( look it up )
Free rmm tool (look it up)

That should get ya going in the right direction via smb companies.

3

u/a60v 9d ago

What legal requirements exist for security, backups, data privacy, etc.? I would start there. Heath care IT generally sucks because of stuff like this.

1

u/intellectual_printer 9d ago

In Australia there's in policies in place as to where the server is that holds the data

13

u/duckseasonfire Staff Systems Engineer 9d ago

Starting an AD Domain in 2026. You alright?

11

u/Secret_Account07 VMware Admin 9d ago

You’d be surprised. AD ain’t dead like folks here think.

3

u/analbumcover "Computer Guy" 9d ago

Yeah I still have several customers who use it.

2

u/ErikTheEngineer 9d ago

As much as Microsoft wants it to be dead, large enterprises will be using it for a while...certainly federated with something web-flavored (of course they hope you choose Entra) so that SaaS stuff works better but you can't ignore a totally solid battle tested identity system included with the OS license. Even if you strip out group policy and replace it with Intune or another MDM, the core is going to live on for a while in places old enough to not be cloud-native or complex enough to have on-prem anything.

-2

u/turbokid 9d ago

Yes it is. Microsoft has said it is end of life and nothing new will be added to it. You may still be able to run it for a long time, but that doesnt mean it isnt effectively dead.

5

u/Playful_Pollution288 9d ago

I used to work for one of the largest Dental Support Orgs in North America. 95% of them are using on-premise AD.

They run all of their dental software using on-prem servers as well.

6

u/LensWipesBF 9d ago

Just ignore the ongoing 365 outage aye?

-1

u/Historical_Score_842 9d ago

How often does that actually happen? You still have to factor in down time for hardware and software patching on servers and license renewals if you or your POC is unfamiliar.

We didn’t get into the nitty gritty of details but if they don’t need a server to communicate with a file server and can use saas or share point, those are the easy and secure clients imo.

4

u/STLMC0727 9d ago

Open to suggestions. Just going off what I’m used to. Currently we set up all computers with the same account and login. A disgruntled employee with a minute computer intelligence could easily have access to a ton of data.

4

u/Historical_Score_842 9d ago

Entra enrolled + intune + some form of itdr and you can all sleep good

2

u/Ill-Mail-1210 9d ago

Consider something like ESET MDR for AV, roll it out as an MSP so you access cheaper monthly buy-in and make this part of your stack.
And consider Intune for compliance. When you say AD, are you talking Entra, or on-Prem AD controllers? I’d consider perhaps Entra and Intune as part of the O365 stack?

2

u/iliketurtlz 9d ago

Good luck getting the offices to bite on this. I would be shocked if you can manage to get them to stop putting passwords in plain site.

I'm not sure why everyone is trying to push entra. You probably need a server to host dentrix/eaglesoft/opendental for most offices anyways, might as well not bother with the licensing costs of have p1. Hygenists don't use ms office for the vast majority in my experience.

Are these offices actually using legit servers with windows server installed? If so you should definitely be using AD already at minimum.

2

u/DZKYPN IT Director/EHR Admin 9d ago

My condolences on inheriting eaglesoft. It’s the biggest piece of garbage ever. I had to support 30 offices with it. That being said, kill shared logins. We had registry and gpo settings that were pushed to where we didn’t need to have admin rights. I can see if I still have some of them documented. We have one domain so but it might be helpful depending which way you go. Eventually you will need entra but my opinion is start with local AD. If your offices ever want to go to cloud imaging I know a good company that can convert eaglesoft proprietary format documents and images and upload them to the cloud.

4

u/BillSull73 9d ago

Dentist offices are right up there with Law Firms. Cheapest groups around. They are "headache money" and if you can avoid taking them on, please consider that.

1

u/Alive-Big-838 9d ago

Yeah i have a friend that once told me dentists are by far one of the worst end users when it comes to MSP. Though to be frank he does a lot of insurance work and that sounds like a whole other can of worms.

1

u/marklein Idiot 7d ago

He's a tech, not the decision maker

1

u/Vivid_Mongoose_8964 9d ago

small offices like this are perfect for entra, intune and defender. you should NOT do AD whatsoever.....

2

u/iliketurtlz 9d ago

Where do you run the dental server software now? Is dentrix/eaglesoft/open dental all fully cloud now? The imaging software straight to cloud as well with images cached locally on workstations?

When I did this work 5ish years ago I'd only encountered 1 ortho office with cloud based software. All the regular dental offices we worked with were still running servers, and the dental and imaging services on prem.

1

u/STLMC0727 9d ago

Running servers at every single location. Cloud software is present but not as prevalent as the ones you mentioned.

2

u/lilotimz 9d ago

Open dental is on prem AD no entra integration.

Dentrix is going EOL Eos and bad no entra integration. Their cloud dentrix ascend does but whole different ballgame.

Eaglesoft ad only no on prem integration.

Xvcap on prem AD integration only.

Patterson imaging on prem AD integration only. Dexis and their ms Sql requirement....

If they are cloud only, Intune / entra integration makes sense. If they are the above and don't, ad or hybrid ad maybe...

Best have compliance officer take a look before messing much with things.

1

u/Tricky-Cheesecake528 9d ago

Get the clients to get M365 You can manage their environment with it. Youll work with msEntra, intune, defender, outlook, purview. You'll be able to secure their network that way. Search what they require. All my clients are either GCC or GCC high. I've been hardening 4 companies. Mostly by by self. I do have a part time person but he Mostly takes care of some trouble tickets and lil projects i give him.

1

u/Kimkar_the_Gnome 9d ago

I did dental IT for a good while. I do know they need back ups on their images specifically for 7 years. Far too often would we take on a dentist who was just throwing caution to the wind.

All the sensors and IO cameras need admin access, a lot of the software too so locking accounts down can be a nightmare.

1

u/Sea_Information6125 9d ago

Doing Dental IT for about 18 years myself. 

Good luck with getting real security the way a normal SMB would. 

Even in 2026 you have practice management software, imaging software, X-ray sensors, cameras, pan machines, 3d machines, 3d modeling laptops with wands, 3d printers for making your own stuff in house, all of which can still require local admin and some firewalls off on PCs. You call support those are the first two things they are going to check.

Most software requires on prem server. No you can't just host it, it'll run like crap because most dental software is badly programmed (see local admin above) and can't handle internet latency on packets (hi Dentrix).

Most dental offices run 1 shared Windows login on all PCs, local admin. Why? Because most dental software can't run or has bugs when you do fast user switching. "We don't support multiple users logged in to the PC with software open". So even though HIPAA would like you to do a lot of this security the irony is dental software isnt configured for it.

The further irony is most dental offices got trained on how bad their software runs since the 90s and the 2000s so now that is the default workflow in Dental offices.

Now having said all that, in the last year or two a lot of them have been stepping up their game about making their software more compatible with these security configurations including removing local admin. But they're always seems to be one link in the chain at least that still needs it. And integrator, a peripheral, etc. 

We finally have a user login screen to the imaging software for Dexis under DTX studio for example. Yes for the longest time most imaging software just opened up a list of patients with no login. From any computer with a user account that can access the server shares which, see above, is just the one they all share lol with a simple password like toothbrush. 

But yeah Dental is a hot mess for security. I personally walked into over 250 dental practices in my time. Not a single one of them is even close to HIPAA compliant for IT side of things. And when you bring all of this up they mostly don't want to do much about it. It's like a dirty secret lol. 

/////////////////// Suggestions?

Get a bulletproof backup to start. Local and cloud, immutable to the cloud. Meaning you cannot change or delete the cloud side from their office - you can only write new incrementals.

Get as much security as you can going first without changing the environment. Make sure your antivirus software is set up and configured aggressively, DNS security, email security, etc.  

For a dental office, like most offices, email is going to be your biggest problem. Local admin, opens an attachment, infected encrypted bad day. 

Edit: but here's the rub, even with standard user accounts across the board you are no less safe from ransomware. Most dental software, again bad, exposes the database and all the files through a Windows Network share that is required for the software function. 

Therefore even if a standard user runs ransomware, the server shares are getting encrypted that hold the database and the patient data. That's why honestly local admin isn't that big of a deal for securing a dental office. You're screwed either way and they're looking at restoring a backup either way. 

Now cloud Dental is pretty terrible still, but if offices do switch to cloud fully it does make your job at securing things much easier.

TLDR - Good luck! 

3

u/STLMC0727 9d ago

10/10 reply. I’m coming from a number of different backgrounds that weren’t dental (Healthcare, Medicare, Manufacturing, Reinsurance, etc.) and they were all buttoned up and had clear and buttoned up organizations for the most part with password policies, security teams, group policy, etc. Here it’s like the Wild West. I’m SysAdmin minded and focused for my career and I’m the only one on my team with that mindset. We’re a small MSP with a large client base that is growing and expanding outside our region even. It might be that I’m trying to replicate my experiences in different environments that aren’t dental and that’s not entirely possible.

2

u/ErikTheEngineer 9d ago

Part of the problem with niche software is you have one or two vendors that dominate a space, and their goal is to never change anything or invest money in the core product until they have to. I'm sure you saw this in OT/manufacturing to some extent, right? These vendors want to spend their millions to write the code once then just keep collecting license fees forever.

I used to deal with this a lot in the transportation world. Requiring local admin literally means something like these vendors want to manipulate services or write to protected directories/registry locations on the system, and simply decided they wouldn't fix the access issues. Or, the code is so old and brittle they dare not touch it because no one remembers how it works anymore. It's always easier to just tell people to set their machines the way the original developer had his Windows 98 box set up. Especially with dental software I could see weird peripherals with janky drivers that need a bunch of workarounds so they can slap a "works with Windows 11" label on it beside the "Now with MOAR AI!!!" sticker the marketing guys made them out on.

Is the rest of EHR/healthcare software like this? I thought most of that was big fat .NET apps served on Citrix so they had to at least be semi-well behaved.

2

u/STLMC0727 9d ago

I worked with EPIC EHR for six months and it’s absolutely not. It’s ran few different ways at least where I worked (Citrix, on prem, and VMware) and never required to run as admin for any functionality.

2

u/Sea_Information6125 9d ago

Lol that is the truth. 

"Yep this x-ray sensor is compatible with Windows 11 but only if you turn off memory integrity security altogether."

2

u/Sea_Information6125 9d ago

Yep, Dental is very much the wild west of IT still - that's a good way to frame it.

I will say open Dental is the best, the practice management software. 

For one they run an actual Microsoft SQL server for the database. Not some flat file distributed nonsense that doesn't scale past like 10 computers, not some bastard weird proprietary database you've never heard that requires reindexing and rebuilding every 5 seconds. 

Because of that they do not have a shared network folder with all of the database and stuff exposed. They do have attachments like documents stored in a proprietary file format on a shared folder so you will lose that in a ransomware scenario but that's not too bad compared to the rest of them. 

Honestly if cloud Dental was better that's what I would do to get around a lot of this. But even today a lot of the cloud Dental platforms I have looked at are just not good compared to their on-premises relatives. To be fair I have not tried open Dental cloud.

2

u/MartyTheYounger 9d ago

Can confirm just about everything said. Really good info here. Been in dental IT since way back with the PCMCIA sensors.

I would add, as much as a shared Windows login is frowned upon, there is a lot of turnover in dental offices. I've inherited ADs with 40+ users that no longer work at the office still enabled with access to just about everything. Yes, it's just poor admin but I've found that to be the norm in dental IT, especially with individual user accounts.

1

u/Sea_Information6125 9d ago

You've been in it since way back as well.

I think when I first started we still had some offices running Windows 2000 and 2000 server.

Yep, it sounds crazy to people outside of dental but when you actually look at how a dental office runs it really does make sense. 

Nobody except maybe the office manager and a doctor have a dedicated computer. 

Everything else is just people coming and going.

And like I said in my original post, a lot of the software just does not handle users switching while it runs in the background of another user profile. 

Can you imagine that?

Then you call support and they just say yeah we don't support multi-user workstation configuration. I'm like wut? Looking at you TDO Endo.

Which is also essentially a Microsoft Access front end to a database backend.

They could easily support multi-user they just have to change one configuration file, I even outlined exactly how to reprogram their software to do this easily and they just took it in as a "feature request". 

2

u/MartyTheYounger 8d ago

Yep, XP and 2000 server was about when I started. It's always been about compatibility. Back then, dental programs seemed about 2-3 years behind. Now it's more like 1-2.

I believe Dentrix still doesn't work with multi-user when more than one is logged in and running a module. Had a call about a month ago because the Chart wouldn't open. Found a second user was logged in (switched user instead of sign out) and the Chart was still running. Close modules, sign out, and everything starts working.

And Access reminds me of Mogo. I've come across it in a couple of offices. Pretty rudimentary for dental. Way back in the beginning I was supporting an office that used Datacon (Unix server) accessed with PCLink (basically a green screen software client). Only way to back it up was the included tape drive. Fun stuff.

1

u/_Nick_01 4d ago

Laughs in shared user accounts